Skip to content

apollo_starknet_os_program,starknet_os: add the Cairo0 proof-fact fold tree - #15093

Closed
einat-starkware wants to merge 0 commit into
claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digestfrom
claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold
Closed

einat-starkware wants to merge 0 commit into
claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digestfrom
claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Fourth PR of the privacy proof-fact fold stack. Adds the fold tree above the leaf digest in Cairo0: fold_block_proof_facts folds a block's ProofFactsReference array into the block's root fold entry (leaf entries, pairwise folding with a carried trailing entry, single-transaction self-fold), and compute_fold_digest computes the digest the Cairo circuit verifier outputs for that entry. Still not reachable from the OS program — the OS output wiring lands in #15064.

ProofFactsReference carries each transaction's leaf_circuit_index alongside its proof facts, and build_leaf_entries stamps each leaf with the indexed hash from the allowed-circuits table (range-checked in #15092's getter). The production registry keys leaf circuits by trace size, so the index becomes real per-transaction OS input on the production swap; until then everything records index 0.

Tested for bit-exact agreement with the Rust mirror across tree shapes exercising the pairing and carry rules (N = 1, 2, 3, 4, 5, 7).

Stack: leaf digest (#15090) ← rust tree fold (#15091) ← cairo leaf digest (#15092) ← this PR ← OS output wiring (#15064) ← registry pin (#15086) ← verifier task (#15088) ← combined test (#15095).

🤖 Generated with Claude Code

https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4

@cursor

cursor Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes cryptographic folding logic that must stay bit-exact with Rust, but the new Cairo entry points are isolated from production OS execution until output wiring lands.

Overview
Adds the Cairo0 proof-fact fold tree above the existing leaf digest so a block’s per-transaction proof facts can be folded into the root entry the privacy verifier expects. New Cairo helpers fold_block_proof_facts (pairwise folds over a block’s proof-fact references, including a carried trailing entry and the single-transaction self-fold case) and compute_fold_digest (Blake2s digest of a fold entry) mirror the Rust fold stack; build_leaf_entries builds leaf fold entries using each tx’s leaf_circuit_index and the allowed leaf-verifier circuit hash table.

The fold program is compiled and exercised via PROOF_FACT_FOLD_BYTES cross-tests against the Rust mirror for tree sizes N = 1, 2, 3, 4, 5, 7. This stack step is not wired into the OS program output yet (follow-up #15064).

Reviewed by Cursor Bugbot for commit 0ce5d55. Bugbot is set up for automated code reviews on this repo. Configure here.

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 3893cae to b23d2c2 Compare September 2, 2026 12:13
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch 2 times, most recently from 89fb31b to f3a733e Compare September 2, 2026 12:29
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch 2 times, most recently from f0196fe to ed8eb88 Compare September 2, 2026 12:45
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from f3a733e to 151d20a Compare September 2, 2026 12:45
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from ed8eb88 to d33ec72 Compare September 2, 2026 13:11
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from 151d20a to 6b6cc46 Compare September 2, 2026 13:11
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from d33ec72 to efaa234 Compare September 2, 2026 13:41
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from 6b6cc46 to 42977ca Compare September 2, 2026 13:41
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from 42977ca to 6c70dbe Compare September 17, 2026 13:36
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch 2 times, most recently from 1fcfd19 to 02eab67 Compare September 22, 2026 09:22
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from 6c70dbe to d6004c1 Compare September 22, 2026 09:22
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 02eab67 to c8828fe Compare September 23, 2026 09:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from d6004c1 to b0e4d06 Compare September 23, 2026 09:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from c8828fe to 0ce5d55 Compare September 23, 2026 12:59
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold branch from b0e4d06 to 0ce5d55 Compare September 23, 2026 13:00

Copy link
Copy Markdown
Contributor Author

Closing: the stack was restructured around a first milestone — verifying a single transaction's proof against the OS output — and proof-fact folding over several transactions is deferred to a later phase. The Cairo0 fold tree from this PR (pairwise layers, carry rule, multi-leaf fold_block_proof_facts) will return in that phase; the single-transaction self-fold it needs today moved into #15092. This PR's branch now aliases #15092's head so the stack chain stays intact.


Generated by Claude Code

@einat-starkware
einat-starkware removed this pull request from stack #15094 September 28, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants